bowsing over IPSEC Tunnel

G

Guest

I have just connected two sites using IPSEC over internet using CISCO PIX.
both are different domains. I can connect using IPADDRESS but I need to be
able to browse using my network places. and then I want to create a trust
between two domains. I am using windows 2000 but soon will upgrade to windows
2003.

Please help me.

I am not expert but I think I have to use WINS. CAN please also tell me a
best way to setup DNS becouse my DNS seems to be working allright but
nslookup command gives no result.
 
P

Phillip Windell

Browsing requires WINS and "Netbios of TCP/IP"

Trusts requires DNS.

The fact that you are using IPSec doesn't really have anything to do with
it,..it would be the same if it was standard VPN or a private lease
line,..or even just two subnets on the same LAN with a Domain in each
subnet.
 
H

Herb Martin

Amad Malik said:
I have just connected two sites using IPSEC over internet using CISCO PIX.
both are different domains.

re: "different domains"

This complicates both DNS and NetBIOS resolution.
I can connect using IPADDRESS but I need to be
able to browse using my network places. and then I want to create a trust
between two domains.

Both of those require NetBIOS name resolution and since
you are working across routers this pretty much means you
need a COMMON WINS Server database (as you seem to
indicate below.)
I am using windows 2000 but soon will upgrade to windows
2003.

Likely irrelevant to your problem.
Please help me.

I am not expert but I think I have to use WINS.

Yes. You need WINS servers.

Probably one in each network, AND in that case they
must replicate.

Each domain's Domain Master Browser (PDC Emulator,
or PDC in NT4) must be able to use NetBIOS to find the
other Domain Master Browser.

Also note, that EVERY machine in both networks should
use the same WINS database (same WINS server or a
replicating set of WINS servers).
CAN please also tell me a
best way to setup DNS becouse my DNS seems to be working allright but
nslookup command gives no result.

nslookup ALWAYS gives SOME results.
(Even if they are not what you wish.)

We cannot solve a DNS problem without the symptoms
but...

Since you have two domains, it is likely that the DNS
servers on one side of the IPSec must hold "secondary"
DNS zones for the other DNS zone (which is presumably
mainly on the other side of the IPSec routers.)

THIS is one thing that might be improved by using Win2003
DNS servers, since they includes stub zones and conditional
forwarding (which might handle the cross resolution better.)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top